Scheduling

Task scheduling

Task scheduling is a system management feature that allows you to automate routine jobs to run once or on a recurring basis.

Time zones and seasonal time changes

Tasks are scheduled in Coordinated Universal Time (UTC). Because UTC remains constant year-round, scheduled tasks do not automatically adjust for local variations such as summer time or Daylight Saving Time. For example, a task scheduled for 2:00 a.m. during standard time runs at 3:00 a.m. during summer time.

Automatically scheduled tasks

The system automatically schedules these tasks:

  • A one-time task to download and install the latest VDB, at initial setup.

  • A weekly task to download the latest available patches, maintenance releases, and, starting at initial setup.

  • A daily task to updated certificate revocation lists (CRL), when you configure user or audit log certificates.

Guidelines for scheduled tasks

This section provides general scheduling guidelines. Refer to Scheduled task types for task-specific guidelines and prerequisites.

When to run tasks

Follow these guidelines when scheduling tasks:

  • Automatically scheduled tasks: Review automatically scheduled tasks to make sure they run at the right time for your environment.

  • Traffic inspection and flow: Schedule tasks that might interrupt traffic during maintenance windows.

Scheduling task sequences

This table lists outcomes that require multiple tasks in sequence. Leave enough time so that each task can finish before the next begins.

Table 1. Outcomes requiring multiple scheduled tasks

Outcome

Tasks

VDB update

  1. Download Latest Update

  2. Install Latest Update

Software upgrade

  1. Download Latest Update

  2. Push Latest Update (devices only)

  3. Install Latest Update

  4. Deploy Policies

    Note

     

    For more information about software upgrades, including additional restrictions and recommended actions if an upgrade is unresponsive or fails, refer to the upgrade guide for your Firewall Management Center version: Secure Firewall Threat Defense upgrade guides for Firewall Management Center.

Scheduled task types

This section describes the available scheduled task types (Job Type in the scheduler), as well as options, guidelines, and requirements for each task.

Backup

Purpose: Back up managed devices.

Options:

  • Backup Type: Device

Guidelines:

  • Supported devices: Some devices, such as devices in the public cloud, cannot be backed up.

  • Simultaneous backups: Back up no more than 20 devices per task. Do not schedule multiple backup tasks for the same time; start with 30 minutes between backups.

  • Bandwidth: If you are transferring backup files, consider scheduling backups during periods of low network use.

Download CRL

Purpose: Download certificate revocation list (CRL) updates. The system automatically schedules daily CRL updates when you configure user or audit log certificates in the system configuration. Use the scheduler to change the update interval or run a one-time update. Disabling the configurations removes the task.

Download latest update

Purpose: Download the latest maintenance releases, patches, and VDB update. Initial setup schedules a weekly download of the latest applicable updates.

Options:

  • Update Items: Choose Vulnerability Database, Software, or both.

Guidelines:

  • Supported software upgrade types: You can download maintenance updates and patches. Major upgrades are not supported.

  • Required task order: To update the VDB or to upgrade the Firewall Management Center, download then install. To upgrade a managed device, download, push, then install. Each task must finish before the next begins.

  • Bandwidth: Consider scheduling downloads during periods of low network use.

Push latest update

Purpose: Push a downloaded software upgrade package to a managed device so that you can upgrade the device.

Options:

  • Device: Choose a device or device group.

Guidelines:

  • Supported upgrade types: You can push maintenance updates and patches. Major upgrades are not supported.

  • Required task order: To upgrade the Firewall Management Center, download then install. To upgrade a managed device, download, push, then install. Each task must finish before the next begins.

  • Bandwidth: Consider scheduling pushes during periods of low network use.

Install latest update

Purpose: Install a maintenance release, patch, or VDB update.

Options:

  • Update Items: Choose Vulnerability Database or Software.

  • Device: For software updates, you can choose the Firewall Management Center, a device, or a device group. For VDB updates, you must choose the Firewall Management Center.

Guidelines for VDB updates:

  • Required task order: To update the VDB, download then install. Download must finish before install begins.

  • Do not perform tasks related to mapped vulnerabilities while the VDB is updating. Even if the Message Center shows no progress for several minutes or indicates that the update has failed, do not restart the update. Instead, contact Cisco TAC.

  • Deploy during a maintenance window to implement changes: Snort typically restarts during the first deployment after VDB update. Restarting the Snort process briefly interrupts traffic flow and inspection on all devices, including devices configured for high availability or clustering.

Guidelines for software upgrades:

  • Supported upgrade types: You can install maintenance updates and patches. Major upgrades are not supported.

  • Required task order: To upgrade the Firewall Management Center, download then install. To upgrade a managed device, download, push, then install. Each task must finish before the next begins.

  • Grouped devices: Use simple device groups to upgrade multiple devices with one scheduled task. The system upgrades the targets one at a time. In high availability or clustered deployments, devices use the normal upgrade behavior.

  • Upgrade devices during a maintenance window due to effects on traffic inspection and flow: For high availability or clustered devices, traffic inspection and flow are not interrupted during upgrade. For standalone devices, interface configurations determine whether traffic is dropped or passed without inspection.

  • Deploy during a maintenance window to implement changes: You must deploy after software upgrades. Snort typically restarts during this first deployment. Restarting the Snort process briefly interrupts traffic flow and inspection on all devices, including devices configured for high availability or clustering.

Update URL filtering database

Purpose: Obtain the latest URL filtering data from Cisco. By default, when you enable URL filtering, automatic updates are enabled. However, if you need to control exactly when these updates occur, use the scheduler.

Guidelines:

  • Licenses: URL Filtering

  • Prerequisite configurations: You must enable URL filtering to schedule this task. Disable automatic updates on Integration > Other Integrations > Cloud Services.

  • Update size, duration, and bandwidth: Daily updates are typically small. With longer intervals, expect larger downloads and additional time for the changes to propagate, and consider scheduling during periods of low network use.

Schedule a task

Before you begin

Before you schedule a task:

Follow these steps to schedule a task.

Procedure


Step 1

Choose System (system gear icon) > Tools > Scheduling and click Add Task.

Step 2

Choose a Job Type and configure the task-specific parameters.

Refer to Scheduled task types for the specific options and restrictions for each task.

Step 3

Specify the schedule details: once or recurring, start time, and frequency.

Step 4

Enter a name for the task, and optionally, a comment and email addresses for status notifications.

You can see comments when you view task details in the calendar.

Step 5

Click Save.


Your task is scheduled and will run at the configured time.